Guide

DNSSEC for .nl domains

DNSSEC adds cryptographic signatures to DNS so resolvers can detect tampering. On NovaMX, authoritative DNS for your zone is signed by default when DNSSEC is enabled for the domain.

What you protect

Without DNSSEC, an attacker could redirect visitors or mail by publishing false DNS answers. With DNSSEC, validating resolvers reject answers that do not match the signed chain of trust from the root to your domain.

NovaMX and the .nl chain

For .nl domains the parent registry (SIDN) must publish a DS record that matches your zone’s DNSKEY. NovaMX signs your zone on authoritative DNS and helps you publish or update the DS record at the registrar when you enable or rotate DNSSEC in My NovaMX.

Typical steps in My NovaMX

  1. Open the domain in My NovaMX and enable DNSSEC if it is not already active.
  2. Review the DS digest shown in the portal and confirm publication at the registrar when prompted.
  3. Wait for DNS propagation (usually minutes to a few hours), then run an external DNSSEC test.
  4. After key rollovers, follow the portal guidance so old and new DS records overlap during the transition.

Verify externally

Run the Internet.nl website test or a DNSSEC debugger to confirm the chain is valid end to end. Domain checks in My NovaMX highlight DNSSEC gaps when your package includes them.

Domains that are not .nl

The idea is the same: NovaMX signs your zone and you publish a DS record at the registry or registrar that matches. Parent registries differ in how you submit DS data. The portal shows the digest and instructions for your TLD.

Common mistakes

Removing NovaMX nameservers while a DS record still points at your old signed zone breaks validation. Skipping the overlap period during key rollover can make the domain unreachable for validating resolvers. Enabling DNSSEC at the registrar without matching keys in the NovaMX zone causes SERVFAIL for signed queries.

When you are stuck

Check the DNSSEC status card in My NovaMX for the next action. Run Internet.nl after propagation waits. Open Messages if DS publication at an external registrar fails repeatedly.